Take a Payment
Take a payment on our payment page: create a hosted session, send your customer to it, then retrieve the session status to find out what happened.
Create a payment session
Create a payment session
POST /hosted/rest/sessions/{instId}/payments{
"session": {
"returnUrl": {
"url": "https://www.example.com/return"
}
},
"transaction": {
"money": {
"currency": "GBP",
"amount": {
"fixed": 25.00
}
},
"merchantReference": "aReference"
}
}curl -X POST "{targetEnvironmentPath}/hosted/rest/sessions/{instId}/payments" \
-u "{apiUser}:{apiPassword}" \
-H "Content-Type: application/json" \
-d '{
"session": {
"returnUrl": {
"url": "https://www.example.com/return"
}
},
"transaction": {
"money": {
"currency": "GBP",
"amount": {
"fixed": 25.00
}
},
"merchantReference": "aReference"
}
}'HTTP/1.1 201 Created
{
"sessionId": "SMjo-nVACrY1K8pP7Vfs-iQOF",
"redirectUrl": "https://secure.mite.pay360.com/hosted/SMjo-nVACrY1K8pP7Vfs-iQOF/begin/SMjo-nVACrY1K8pP7Vfs-iQOF",
"status": "SUCCESS"
}- The currency reference uses the ISO 4217 alphabetic code.
- The customer's browser will be redirected to the returnUrl once transaction processing has finished.
- This example creates a hosted session to collect a payment for a specific amount. Other amount options are available, including letting the customer choose from options or enter an amount within a range — see Offering amount options below.
- In the response the key field is status. SUCCESS means the hosted session is ready, anything else is a failure.
- Only on success, redirect the user's browser to the returned url, or include it in your site within an iframe, and the customer will be presented with the payment form.
- The response field sessionId is our unique id for this hosted session. Keep this to retrieve the status of the session.
- New fields may be added to the response at any time, so ensure your integration will not mind unexpected response elements. Existing response fields will not be removed without notice.
- A hosted session binds to the first browser to visit the redirectUrl, any attempts to visit the hosted session from another browser will produce an error page.
Naming the customer on the session
Send the customer's own reference in customer.identity.merchantCustomerId, along with their details the first time you use it, and we hold the customer against the session.
Payment session for a new customer
POST /hosted/rest/sessions/{instId}/payments{
"transaction": {
"money": {
"currency": "GBP",
"amount": {
"fixed": 25.00
}
},
"merchantReference": "TXN-0002",
"description": "Sample Payment"
},
"customer": {
"identity": {
"merchantCustomerId": "CUST-0001"
},
"details": {
"name": "John Smith",
"emailAddress": "[email protected]",
"telephone": "+441234567890"
}
},
"session": {
"returnUrl": {
"url": "https://www.example.com"
}
}
}curl -X POST "{targetEnvironmentPath}/hosted/rest/sessions/{instId}/payments" \
-u "{apiUser}:{apiPassword}" \
-H "Content-Type: application/json" \
-d '{
"transaction": {
"money": {
"currency": "GBP",
"amount": {
"fixed": 25.00
}
},
"merchantReference": "TXN-0002",
"description": "Sample Payment"
},
"customer": {
"identity": {
"merchantCustomerId": "CUST-0001"
},
"details": {
"name": "John Smith",
"emailAddress": "[email protected]",
"telephone": "+441234567890"
}
},
"session": {
"returnUrl": {
"url": "https://www.example.com"
}
}
}'HTTP/1.1 201 Created
{
"sessionId": "SMjrlEyyTsNRDm5JxhhnZJvk-",
"redirectUrl": "https://secure.mite.pay360.com/hosted/SMjrlEyyTsNRDm5JxhhnZJvk-/begin/SMjrlEyyTsNRDm5JxhhnZJvk-",
"status": "SUCCESS"
}Once we know the customer, the reference on its own is enough — we take the details we already hold.
Payment session for an existing customer
POST /hosted/rest/sessions/{instId}/payments{
"transaction": {
"money": {
"currency": "GBP",
"amount": {
"fixed": 25.00
}
},
"merchantReference": "TXN-0003",
"description": "Sample Payment"
},
"customer": {
"identity": {
"merchantCustomerId": "CUST-0001"
}
},
"session": {
"returnUrl": {
"url": "https://www.example.com"
}
}
}curl -X POST "{targetEnvironmentPath}/hosted/rest/sessions/{instId}/payments" \
-u "{apiUser}:{apiPassword}" \
-H "Content-Type: application/json" \
-d '{
"transaction": {
"money": {
"currency": "GBP",
"amount": {
"fixed": 25.00
}
},
"merchantReference": "TXN-0003",
"description": "Sample Payment"
},
"customer": {
"identity": {
"merchantCustomerId": "CUST-0001"
}
},
"session": {
"returnUrl": {
"url": "https://www.example.com"
}
}
}'HTTP/1.1 201 Created
{
"sessionId": "SMjpEpId4uPpLAofG9VbrrJ1g",
"redirectUrl": "https://secure.mite.pay360.com/hosted/SMjpEpId4uPpLAofG9VbrrJ1g/begin/SMjpEpId4uPpLAofG9VbrrJ1g",
"status": "SUCCESS"
}Offering amount options
Instead of a fixed amount, money.amount.suggested lets the customer choose. Offer a set of amounts with choice.option, a range they can type an amount into with range, or — as below — both.
Payment session offering various amount options and custom input
POST /hosted/rest/sessions/{instId}/payments{
"transaction": {
"money": {
"currency": "GBP",
"amount": {
"suggested": {
"choice": {
"option": [
"10.00",
"20.00",
"50.00"
]
},
"range": {
"min": 1.00,
"max": 150.00
}
}
}
},
"merchantReference": "TXN-0004",
"description": "Sample Payment"
},
"session": {
"returnUrl": {
"url": "https://www.example.com"
}
}
}curl -X POST "{targetEnvironmentPath}/hosted/rest/sessions/{instId}/payments" \
-u "{apiUser}:{apiPassword}" \
-H "Content-Type: application/json" \
-d '{
"transaction": {
"money": {
"currency": "GBP",
"amount": {
"suggested": {
"choice": {
"option": [
"10.00",
"20.00",
"50.00"
]
},
"range": {
"min": 1.00,
"max": 150.00
}
}
}
},
"merchantReference": "TXN-0004",
"description": "Sample Payment"
},
"session": {
"returnUrl": {
"url": "https://www.example.com"
}
}
}'HTTP/1.1 201 Created
{
"sessionId": "SMjov7cJjehNBOqo3_PwDqx0R",
"redirectUrl": "https://secure.mite.pay360.com/hosted/SMjov7cJjehNBOqo3_PwDqx0R/begin/SMjov7cJjehNBOqo3_PwDqx0R",
"status": "SUCCESS"
}Retrieve the session status
Retrieve session
GET /hosted/rest/sessions/{instId}/{sessionId}/statuscurl -X GET "{targetEnvironmentPath}/hosted/rest/sessions/{instId}/{sessionId}/status" \
-u "{apiUser}:{apiPassword}" \
-H "Accept: application/json"HTTP/1.1 200
{
"status": "SUCCESS",
"hostedSessionStatus": {
"sessionId": "SMjo-nVACrY1K8pP7Vfs-iQOF",
"context": "https://secure.mite.pay360.com/hosted",
"sessionState": "STARTED",
"transactionState": {
"transactionState": "PROCESSING"
}
}
}HTTP/1.1 200
{
"status": "SUCCESS",
"hostedSessionStatus": {
"sessionId": "SMjo-nVACrY1K8pP7Vfs-iQOF",
"context": "https://secure.mite.pay360.com/hosted",
"sessionState": "TERMINATED",
"transactionState": {
"id": "11802480907",
"transactionState": "SUCCESS"
}
}
}HTTP/1.1 404
{
"status": "FAILED",
"reasonCode": "exception.sessionState.noSession",
"reasonMessage": "Session not found"
}- Three responses are shown: the session is still being paid or processed, the session has finished with a successful transaction, or the session no longer exists. The second is the one that carries the transaction id.
- The status field is the status of retrieving the hosted session. It has no relation to the status of transaction processing.
- The sessionState of TERMINATED means this session is finished and done. Any future attempts to visit this hosted session will fail.
- The response field hostedSessionStatus.transactionState.id is our unique id for this transaction. You should keep a copy of this reference on your system, and can use it to retrieve full transaction details on the api.
- The api to retrieve a session status is available for 3 hours after the session was last used. After that session details cannot be retrieved.
3D Secure payments
3D Secure authenticates the cardholder with their card issuer before authorisation is requested. The PaySuite payment page handles the whole process for you: it redirects the cardholder to our 3D Secure Server, receives them back, and resumes the transaction. There is nothing to add to the session request, and no resume request to send.
You may optionally provide additional data about the transaction to increase the likelihood of a frictionless flow — see Additional request data. The strongCustomerAuthentication element carries what the issuer may use in their risk analysis: the transaction, the customer, and their history with you — see Strong Customer Authentication tuning. Every field is optional, so send what you have; these four sessions show the shapes it takes.
Requesting a challenge
POST /hosted/rest/sessions/{instId}/payments{
"session": {
"returnUrl": {
"url": "https://www.example.com/return"
}
},
"transaction": {
"money": {
"currency": "GBP",
"amount": {
"fixed": 150.00
}
},
"merchantReference": "aReference"
},
"customer": {
"registered": false,
"details": {
"name": "John Smith",
"emailAddress": "[email protected]",
"telephone": "+441234567890"
}
},
"strongCustomerAuthentication": {
"challengeRequested": "CHALLENGE_REQUESTED"
}
}curl -X POST "{targetEnvironmentPath}/hosted/rest/sessions/{instId}/payments" \
-u "{apiUser}:{apiPassword}" \
-H "Content-Type: application/json" \
-d '{
"session": {
"returnUrl": {
"url": "https://www.example.com/return"
}
},
"transaction": {
"money": {
"currency": "GBP",
"amount": {
"fixed": 150.00
}
},
"merchantReference": "aReference"
},
"customer": {
"registered": false,
"details": {
"name": "John Smith",
"emailAddress": "[email protected]",
"telephone": "+441234567890"
}
},
"strongCustomerAuthentication": {
"challengeRequested": "CHALLENGE_REQUESTED"
}
}'HTTP/1.1 201 Created
{
"sessionId": "SMjqcHCoFIO9Gk59O48fCZvA1",
"redirectUrl": "https://secure.mite.pay360.com/hosted/SMjqcHCoFIO9Gk59O48fCZvA1/begin/SMjqcHCoFIO9Gk59O48fCZvA1",
"status": "SUCCESS"
}- challengeRequested on its own asks the issuer for a particular authentication flow — here a challenge, for a transaction you are not comfortable letting through frictionless.
- The preference we ultimately sent is in threeDSecure.challengeRequest: we override it where scheme rules require a challenge, and the issuer decides in any case. See Strong Customer Authentication tuning.
- The session response is the same whether or not you send strongCustomerAuthentication: the authentication happens after the customer follows the redirectUrl, and what we passed to the issuer ends up in the threeDSecure and strongCustomerAuthentication sections of the transaction.
Digital pre-order payment
POST /hosted/rest/sessions/{instId}/payments{
"session": {
"returnUrl": {
"url": "https://www.example.com/return"
}
},
"transaction": {
"money": {
"currency": "GBP",
"amount": {
"fixed": 50.00
}
},
"merchantReference": "aReference"
},
"customer": {
"registered": false,
"details": {
"name": "John Smith",
"emailAddress": "[email protected]",
"telephone": "+441234567890"
}
},
"strongCustomerAuthentication": {
"merchantRisk": {
"deliveryTimeframe": "ELECTRONIC",
"deliveryEmail": "[email protected]",
"preorder": true,
"preorderDate": "2026-11-01",
"shippingTo": "DIGITAL"
},
"accountInfo": {
"accountOpened": {
"period": "MORE_THAN_60_DAYS"
},
"accountLastChanged": {
"period": "BETWEEN_30_AND_60_DAYS"
},
"passwordLastChanged": {
"period": "MORE_THAN_60_DAYS"
},
"paymentAccountRegistered": {
"period": "MORE_THAN_60_DAYS"
},
"suspiciousActivity": false
}
}
}curl -X POST "{targetEnvironmentPath}/hosted/rest/sessions/{instId}/payments" \
-u "{apiUser}:{apiPassword}" \
-H "Content-Type: application/json" \
-d '{
"session": {
"returnUrl": {
"url": "https://www.example.com/return"
}
},
"transaction": {
"money": {
"currency": "GBP",
"amount": {
"fixed": 50.00
}
},
"merchantReference": "aReference"
},
"customer": {
"registered": false,
"details": {
"name": "John Smith",
"emailAddress": "[email protected]",
"telephone": "+441234567890"
}
},
"strongCustomerAuthentication": {
"merchantRisk": {
"deliveryTimeframe": "ELECTRONIC",
"deliveryEmail": "[email protected]",
"preorder": true,
"preorderDate": "2026-11-01",
"shippingTo": "DIGITAL"
},
"accountInfo": {
"accountOpened": {
"period": "MORE_THAN_60_DAYS"
},
"accountLastChanged": {
"period": "BETWEEN_30_AND_60_DAYS"
},
"passwordLastChanged": {
"period": "MORE_THAN_60_DAYS"
},
"paymentAccountRegistered": {
"period": "MORE_THAN_60_DAYS"
},
"suspiciousActivity": false
}
}
}'HTTP/1.1 201 Created
{
"sessionId": "SMjq5-irbsq9P9ownqGO4dcRb",
"redirectUrl": "https://secure.mite.pay360.com/hosted/SMjq5-irbsq9P9ownqGO4dcRb/begin/SMjq5-irbsq9P9ownqGO4dcRb",
"status": "SUCCESS"
}- Merchandise that is delivered electronically and is not yet available: merchantRisk describes the delivery, and accountInfo the customer's account with you — an established account with nothing suspicious on it makes a frictionless outcome more likely.
- No challengeRequested was sent, so the preference passed to the issuer is
NO_PREFERENCE. - The session response is the same whether or not you send strongCustomerAuthentication: the authentication happens after the customer follows the redirectUrl, and what we passed to the issuer ends up in the threeDSecure and strongCustomerAuthentication sections of the transaction.
Gift card payment with a challenge requested
POST /hosted/rest/sessions/{instId}/payments{
"session": {
"returnUrl": {
"url": "https://www.example.com/return"
}
},
"transaction": {
"money": {
"currency": "GBP",
"amount": {
"fixed": 1000.00
}
},
"merchantReference": "aReference"
},
"customer": {
"registered": false,
"details": {
"name": "John Smith",
"emailAddress": "[email protected]",
"telephone": "+441234567890"
}
},
"strongCustomerAuthentication": {
"challengeRequested": "CHALLENGE_REQUESTED",
"merchantRisk": {
"deliveryTimeframe": "SAME_DAY",
"giftCardPurchase": {
"totalAmount": 1000,
"currency": "GBP",
"count": 20
},
"shippingTo": "OTHER_ADDRESS"
},
"accountInfo": {
"accountOpened": {
"period": "MORE_THAN_60_DAYS"
},
"accountLastChanged": {
"period": "THIS_TRANSACTION"
},
"passwordLastChanged": {
"period": "THIS_TRANSACTION"
},
"paymentAccountRegistered": {
"period": "MORE_THAN_60_DAYS"
},
"activity": {
"purchasesInLastSixMonths": 5,
"transactionAttemptsInLast24Hours": 27,
"transactionAttemptsInLastYear": 32
},
"shippingNameSameAsAccountName": false
}
},
"order": {
"shippingAddress": {
"line1": "123 Fake Street",
"city": "Fakeville",
"postcode": "FV99 6TY",
"countryCode": "GBR"
}
}
}curl -X POST "{targetEnvironmentPath}/hosted/rest/sessions/{instId}/payments" \
-u "{apiUser}:{apiPassword}" \
-H "Content-Type: application/json" \
-d '{
"session": {
"returnUrl": {
"url": "https://www.example.com/return"
}
},
"transaction": {
"money": {
"currency": "GBP",
"amount": {
"fixed": 1000.00
}
},
"merchantReference": "aReference"
},
"customer": {
"registered": false,
"details": {
"name": "John Smith",
"emailAddress": "[email protected]",
"telephone": "+441234567890"
}
},
"strongCustomerAuthentication": {
"challengeRequested": "CHALLENGE_REQUESTED",
"merchantRisk": {
"deliveryTimeframe": "SAME_DAY",
"giftCardPurchase": {
"totalAmount": 1000,
"currency": "GBP",
"count": 20
},
"shippingTo": "OTHER_ADDRESS"
},
"accountInfo": {
"accountOpened": {
"period": "MORE_THAN_60_DAYS"
},
"accountLastChanged": {
"period": "THIS_TRANSACTION"
},
"passwordLastChanged": {
"period": "THIS_TRANSACTION"
},
"paymentAccountRegistered": {
"period": "MORE_THAN_60_DAYS"
},
"activity": {
"purchasesInLastSixMonths": 5,
"transactionAttemptsInLast24Hours": 27,
"transactionAttemptsInLastYear": 32
},
"shippingNameSameAsAccountName": false
}
},
"order": {
"shippingAddress": {
"line1": "123 Fake Street",
"city": "Fakeville",
"postcode": "FV99 6TY",
"countryCode": "GBR"
}
}
}'HTTP/1.1 201 Created
{
"sessionId": "SMjoVb8lpqjBA_oPW0J6Qyv4m",
"redirectUrl": "https://secure.mite.pay360.com/hosted/SMjoVb8lpqjBA_oPW0J6Qyv4m/begin/SMjoVb8lpqjBA_oPW0J6Qyv4m",
"status": "SUCCESS"
}- A large gift card order, shipped somewhere other than the billing address, to an account whose password changed during this transaction: the data says as much, and challengeRequested asks for the cardholder to be challenged.
- giftCardPurchase.totalAmount is in major units, and the shipping address is part of order details rather than of strongCustomerAuthentication.
- The session response is the same whether or not you send strongCustomerAuthentication: the authentication happens after the customer follows the redirectUrl, and what we passed to the issuer ends up in the threeDSecure and strongCustomerAuthentication sections of the transaction.
Reorder payment with a prior authentication
POST /hosted/rest/sessions/{instId}/payments{
"session": {
"returnUrl": {
"url": "https://www.example.com/return"
}
},
"transaction": {
"money": {
"currency": "GBP",
"amount": {
"fixed": 75.00
}
},
"merchantReference": "aReference"
},
"customer": {
"registered": false,
"details": {
"name": "John Smith",
"emailAddress": "[email protected]",
"telephone": "+441234567890"
}
},
"strongCustomerAuthentication": {
"challengeRequested": "NO_CHALLENGE_REQUESTED",
"merchantRisk": {
"deliveryTimeframe": "TWO_OR_MORE_DAYS",
"reorder": true,
"shippingTo": "BILLING_ADDRESS"
},
"accountInfo": {
"accountOpened": {
"date": "2023-07-23"
},
"accountLastChanged": {
"date": "2025-09-21"
},
"passwordLastChanged": {
"date": "2026-03-07"
},
"paymentAccountRegistered": {
"date": "2023-07-23"
},
"activity": {
"purchasesInLastSixMonths": 6,
"transactionAttemptsInLast24Hours": 1,
"transactionAttemptsInLastYear": 12
},
"shippingNameSameAsAccountName": true
},
"priorAuthenticationInfo": {
"reference": "64a09f9b-0d89-4cfe-8de9-9b96fdfa4eb8",
"method": "FRICTIONLESS_AUTH",
"time": "2026-08-11T13:04:54"
}
}
}curl -X POST "{targetEnvironmentPath}/hosted/rest/sessions/{instId}/payments" \
-u "{apiUser}:{apiPassword}" \
-H "Content-Type: application/json" \
-d '{
"session": {
"returnUrl": {
"url": "https://www.example.com/return"
}
},
"transaction": {
"money": {
"currency": "GBP",
"amount": {
"fixed": 75.00
}
},
"merchantReference": "aReference"
},
"customer": {
"registered": false,
"details": {
"name": "John Smith",
"emailAddress": "[email protected]",
"telephone": "+441234567890"
}
},
"strongCustomerAuthentication": {
"challengeRequested": "NO_CHALLENGE_REQUESTED",
"merchantRisk": {
"deliveryTimeframe": "TWO_OR_MORE_DAYS",
"reorder": true,
"shippingTo": "BILLING_ADDRESS"
},
"accountInfo": {
"accountOpened": {
"date": "2023-07-23"
},
"accountLastChanged": {
"date": "2025-09-21"
},
"passwordLastChanged": {
"date": "2026-03-07"
},
"paymentAccountRegistered": {
"date": "2023-07-23"
},
"activity": {
"purchasesInLastSixMonths": 6,
"transactionAttemptsInLast24Hours": 1,
"transactionAttemptsInLastYear": 12
},
"shippingNameSameAsAccountName": true
},
"priorAuthenticationInfo": {
"reference": "64a09f9b-0d89-4cfe-8de9-9b96fdfa4eb8",
"method": "FRICTIONLESS_AUTH",
"time": "2026-08-11T13:04:54"
}
}
}'HTTP/1.1 201 Created
{
"sessionId": "SMjqw6W03XepNhJUYG-fo26UK",
"redirectUrl": "https://secure.mite.pay360.com/hosted/SMjqw6W03XepNhJUYG-fo26UK/begin/SMjqw6W03XepNhJUYG-fo26UK",
"status": "SUCCESS"
}- A repeat purchase by a long-standing customer, where challengeRequested asks for no challenge. The accountInfo periods can be given as dates instead of relative periods.
- priorAuthenticationInfo.reference is the threeDSecure.acsTransactionId of an earlier authentication of the same cardholder, which lets the issuer take it into account.
- The session response is the same whether or not you send strongCustomerAuthentication: the authentication happens after the customer follows the redirectUrl, and what we passed to the issuer ends up in the threeDSecure and strongCustomerAuthentication sections of the transaction.
When using our result page to show the cardholder information, you should review any custom skins to ensure that the message is correctly displayed.
The authentication details are not part of the session status; they are in the threeDSecure section of the transaction.
To try the different 3D Secure scenarios in MITE, the only thing you need to change is the card number you enter on the payment page after following the redirectUrl — the cards enrolled in 3DS on Test Cards, and those that force a particular authentication outcome in Testing in MITE.